Apple — Public PoC Released for CoreGraphics Zero-Day Vulnerability (CVE-2026-86950)
Publication date: October 01, 2026
Category: News
Introduction
Apple has released emergency security updates to address a critical zero-day vulnerability affecting its CoreGraphics rendering engine, officially tracked as CVE-2026-86950. The flaw, which enables arbitrary code execution through the processing of maliciously crafted files, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog following reports of its use in sophisticated attacks against targeted individuals. Recently, security researchers released a public proof-of-concept (PoC) code demonstrating how a modified font within a PDF file can crash unpatched systems, significantly increasing operational risk.
What is CVE-2026-86950? (General Analysis)
CVE-2026-86950 is an out-of-bounds write vulnerability classified under CWE-787, holding a CVSS v3.1 base score of 8.8 (Official Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). This indicates high severity, requiring user interaction (such as opening a file or viewing a document) over a network, without requiring prior privileges or authentication.
The affected component, CoreGraphics, is the core framework responsible for graphics and rendering functions across Apple’s operating systems (including iOS, iPadOS, and macOS). By handling complex visual elements such as images, vectors, and typography fonts, any flaw in its memory management logic exposes the operating system to catastrophic memory corruption, compromising device integrity and confidentiality.
How Does It Work? (Technical Analysis)
The vulnerability stems from a mathematical rounding and data type conversion error within the font rendering and glyph rasterization subsystem of CoreGraphics.
- Initial Entry Flow: The attack triggers when the operating system processes a structured file (specifically a PDF document containing a maliciously designed embedded font). The renderer automatically processes the content when generating thumbnails, previews, or opening the file, aligning with zero-click or low-interaction attack paradigms.
- Numeric Overflow Mismatch: CoreGraphics converts double-precision floating-point coordinates into fixed-point formats, dividing each pixel into a 4096 × 4096 grid. The flaw occurs when a number exceeds 32-bit integer (
int32_t) boundaries. - Instruction Inconsistency: Different internal functions handled overflows differently. While one function (
aa_moveto) used the ARM64 instructionFCVTZSto saturate the value toINT32_MAXorINT32_MIN, a related function (aa_lineto) converted the value to 64-bit integers and applied anXTNtruncation instruction, keeping only the lower 32 bits. - Bounding Box Memory Corruption: When recording a glyph’s path, CoreGraphics builds a bounding box from edge coordinates to allocate a rendering buffer. Due to the truncation bug, subtraction calculations flip signs, creating an undersized bounding box. When the rasterizer draws real edges into this undersized buffer, a classic out-of-bounds write occurs.
“Converting between a double and an int32_t out of bounds constitutes undefined behavior. Before the patch, function discrepancies in handling overflows led to an undersized rendering buffer, allowing adjacent memory corruption when processing complex font structures.”
Affected Systems / Environments
The vulnerability impacts multiple versions of Apple operating system ecosystems prior to the corresponding security patch builds:
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-86950 | CWE-787 (Out-of-Bounds Write) | Code Execution / Memory Corruption | 8.8 (High) | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
- Affected Systems:
- iOS and iPadOS (versions prior to 26.7.1 and prior to the iOS 27 branch).
- macOS Sequoia (versions prior to 15.8.1).
- macOS Tahoe (versions prior to 26.7.1).
Mitigation and Detection
Remediation
The only definitive mitigation is the immediate application of official patches provided by the vendor. There are no application-level configuration workarounds because the flaw resides deep within the operating system’s rendering stack:
- Update iOS and iPadOS to version 26.7.1 or later.
- Update macOS Sequoia to version 15.8.1 or later.
- Update macOS Tahoe to version 26.7.1 or later.
Detection
- Network and Endpoint Monitoring: Inspect traffic and attachment flows in messaging and email applications for PDF files containing anomalous embedded fonts or complex typographical metadata structures.
- Artifact Analysis: Identify anomalies in system services tied to graphical processing (
CoreGraphics,fontd) experiencing unexpected crashes or faults followed by suspicious core dumps.
Wrapping Up
The discovery and subsequent publication of a functional PoC for CVE-2026-86950 significantly heightens operational urgency for system administrators and defensive teams. Because CoreGraphics is deeply embedded in Apple’s visual processing stack, any automatically processed malicious document presents a highly efficient attack vector. The inclusion of this flaw in the CISA KEV catalog and its history of exploitation in targeted campaigns underscore the imperative need to deploy security patches without delay.
References
- Security Affairs. (2026). Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950. Retrieved from https://securityaffairs.com/?p=200175
- Apple Inc. (2026). About the security content of iOS 26.7.1 and iPadOS 26.7.1. Apple Support Advisory. https://support.apple.com/en-us/149226
- Apple Inc. (2026). About the security content of macOS Sequoia 15.8.1. Apple Support Advisory. https://support.apple.com/en-us/149228
- Apple Inc. (2026). About the security content of macOS Tahoe 26.7.1. Apple Support Advisory. https://support.apple.com/en-us/149229
- CISA. (2026). Known Exploited Vulnerabilities Catalog - CVE-2026-86950. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950